Skip to main content
Sign in
Ill Bloom Vulnerability1 decision on this page

Audit log

Every state-changing event for Ill Bloom Vulnerability: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-26 23:03:27Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    DNhR2jGS8nMo…6HiQFac3sha256 → base58
    verifying row…
    canonical bytes (19325 B) ▸
    {"actor":"system:backfill","investigation_id":"6a0b96a9-10af-4600-b44a-e1e01b870cb0","kind":"publish","page_slug":"ill-bloom-vulnerability","published_at":"2026-07-26T23:03:27.894Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Ill Bloom Vulnerability","sections":[{"content":"Ill Bloom is the name given to a class of cryptographic weaknesses affecting certain cryptocurrency wallet applications that used insecure pseudorandom number generators (PRNGs) during the generation of BIP-39 recovery phrases (seed phrases). Disclosed publicly by blockchain security firm Coinspect on or around July 6, 2026, the vulnerability results in recovery phrases with significantly less cryptographic entropy than expected. A standard BIP-39 recovery phrase should draw from an astronomically large keyspace; when the PRNG seeding process is weak or predictable, the effective keyspace collapses to a range attackers can enumerate computationally. The name 'Ill Bloom' is derived from wordplay on the first recovery phrase produced by the vulnerable PRNG, which begins with the words 'illness blossom.' Coinspect stated it identified five vulnerable wallet implementations but has not publicly named any of them at this stage, citing a deliberate staged disclosure strategy intended to avoid providing additional exploitation guidance to attackers while users are still migrating funds. Coinspect also disclosed that it collaborated with wallet developers and security firm SlowMist during the coordinated disclosure process.","heading":"Vulnerability Overview","severity":"critical","sources":[{"credibility":1,"name":"Ill Bloom: Crypto Wallet Vulnerability — Official Disclosure Site","type":"official","url":"https://illbloom.org/"},{"credibility":1,"name":"Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html"},{"credibility":2,"name":"Coinspect warns Ill Bloom flaw may drain more crypto wallets — Crypto.news","type":"news_article","url":"https://crypto.news/coinspect-warns-ill-bloom-flaw-may-drain-more-crypto-wallets/"}]},{"content":"The root cause of Ill Bloom is the use of a deficient PRNG during the wallet creation process. When a user generates a new wallet, the application is required to produce a cryptographically secure random number to seed the BIP-39 mnemonic generation. Applications affected by Ill Bloom instead used a standard (non-cryptographic) PRNG or a PRNG seeded with insufficiently unpredictable state, such as system time or device identifiers. This dramatically reduces the number of possible seed phrases from the theoretical 2^128 (or 2^256 depending on phrase length) to a set small enough for an attacker with modest computational resources to enumerate. Coinspect researchers were able to reconstruct the attack methodology end-to-end: by iterating through the reduced keyspace of phrases the weak generator could produce, deriving the corresponding wallet addresses for each phrase, and then querying public blockchain records to identify which of those addresses held or had held funds. The vulnerability affects all chains simultaneously for any given seed phrase, because BIP-44 key derivation paths for different chains (Bitcoin, Ethereum, Tron, Solana, Polygon, Rootstock, and others) are all derived from the same root seed.","heading":"Technical Root Cause","severity":"critical","sources":[{"credibility":1,"name":"Ill Bloom: Crypto Wallet Vulnerability — Official Disclosure Site","type":"official","url":"https://illbloom.org/"},{"credibility":2,"name":"Coinspect warns Ill Bloom flaw may drain more crypto wallets — Crypto.news","type":"news_article","url":"https://crypto.news/coinspect-warns-ill-bloom-flaw-may-drain-more-crypto-wallets/"},{"credibility":2,"name":"Coinspect Warns of Vulnerability Threatening Thousands of Crypto Wallets — ForkLog","type":"news_article","url":"https://forklog.com/en/coinspect-warns-of-vulnerability-threatening-thousands-of-crypto-wallets/"}]},{"content":"As of the July 2026 public disclosure, Coinspect confirmed that at least $5 million had been drained from vulnerable addresses. The most significant single event was a coordinated sweep on May 27, 2026, in which 431 wallet addresses were drained for a total of approximately $3,140,968. Chain-level breakdown of the May 27 sweep as reported by ForkLog and Coinspect: Bitcoin approximately $2.57 million, Ethereum $285,778, Rootstock $177,225, Tron $80,970, and Polygon $23,473. A single Bitcoin address lost over $1.1 million in this sweep. Subsequently, an additional approximately $2.1 million in USDT was drained from a separately identified exposed wallet, pushing confirmed total losses past $5 million. Coinspect noted that the historical peak value of identified exposed addresses reached $12.56 million in 2022, indicating that some funds were moved or spent by legitimate holders before attackers acted. The analyzed dataset as of June 30, 2026 contained 2,114 funded addresses with on-chain activity spanning September 2018 through May 2026. Coinspect explicitly cautioned that this dataset is a partial sample and the actual number of vulnerable addresses and total losses may be significantly higher, as not all chains or address sets have been fully analyzed.","heading":"Confirmed Financial Losses and On-Chain Impact","severity":"critical","sources":[{"credibility":1,"name":"Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html"},{"credibility":2,"name":"Coinspect Warns of Vulnerability Threatening Thousands of Crypto Wallets — ForkLog","type":"news_article","url":"https://forklog.com/en/coinspect-warns-of-vulnerability-threatening-thousands-of-crypto-wallets/"},{"credibility":2,"name":"'Ill Bloom' flaw puts 2,114 digital wallets at risk: report — CoinGeek","type":"news_article","url":"https://coingeek.com/ill-bloom-flaw-puts-2114-digital-wallets-at-risk-report/"},{"credibility":2,"name":"Ill Bloom Vulnerability Drains $3.1 Million From Crypto Wallets: Are You Exposed? — BeInCrypto","type":"news_article","url":"https://beincrypto.com/ill-bloom-vulnerability-crypto-wallets/"}]},{"content":"Vulnerable seed phrases expose funds across every chain for which keys are derived from that seed. Chains confirmed in Coinspect's analyzed dataset include Bitcoin, Ethereum, Polygon, Tron, Rootstock, and Solana. The official illbloom.org disclosure page lists a broader set of supported chains including BNB Chain, Arbitrum, Optimism, Base, Avalanche, Gnosis, Linea, HyperEVM, and Monad, indicating that Coinspect's address checker covers derivation paths for these networks as well, even if they were not the primary chains in the initial loss tally. The cross-chain nature of BIP-44 key derivation means that a single compromised seed phrase simultaneously exposes all associated addresses on all supported networks.","heading":"Affected Chains and Scope","severity":"critical","sources":[{"credibility":1,"name":"Ill Bloom: Crypto Wallet Vulnerability — Official Disclosure Site","type":"official","url":"https://illbloom.org/"},{"credibility":2,"name":"Thousands of crypto wallets at risk from 'Ill Bloom' vulnerability: Coinspect — TradingView/Cointelegraph","type":"news_article","url":"https://www.tradingview.com/news/cointelegraph:e1ab8d173094b:0-thousands-of-crypto-wallets-at-risk-from-ill-bloom-vulnerability-coinspect/"}]},{"content":"Coinspect's disclosure explicitly states that hardware wallet users are not affected by Ill Bloom. Hardware wallets generate seed phrases using dedicated secure elements that draw entropy from certified, isolated random number sources, making them resistant to this class of PRNG weakness. Most current mainstream software wallets are also reported as not vulnerable. The population at risk is concentrated among users who generated seed phrases using lesser-known or older mobile software wallet applications, potentially including browser extensions. Coinspect identified five distinct vulnerable wallet implementations in its research but has withheld their names publicly as part of a staged disclosure approach, coordinating directly with affected wallet developers and with security firm SlowMist. Reports note that new vulnerable wallets were still being created as recently as the disclosure period in 2026, suggesting that at least some affected applications remained in active use. Users who received a wallet from a third party, who used a wallet application with no documented security audit, or who are uncertain of the wallet software used for their original seed generation are advised to treat their seeds as potentially compromised.","heading":"Affected and Unaffected Wallet Types","severity":"high","sources":[{"credibility":1,"name":"Ill Bloom: Crypto Wallet Vulnerability — Official Disclosure Site","type":"official","url":"https://illbloom.org/"},{"credibility":1,"name":"Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html"},{"credibility":2,"name":"Coinspect warns Ill Bloom flaw may drain more crypto wallets — Crypto.news","type":"news_article","url":"https://crypto.news/coinspect-warns-ill-bloom-flaw-may-drain-more-crypto-wallets/"}]},{"content":"Coinspect published an affected-address checker at illbloom.org that allows users to query whether any of their public wallet addresses appear in the known vulnerable dataset. Users are instructed to input only their public wallet address — not their seed phrase or private key. Coinspect explicitly warned that it will never ask for seed phrases, private keys, transaction signatures, or approvals. If an address matches the vulnerable dataset, the recommended remediation is: (1) create a brand new wallet using a trusted, security-audited wallet application with demonstrated secure entropy generation; (2) generate a new recovery phrase in this new wallet; and (3) immediately transfer all funds to addresses derived from the new seed. Reimporting the compromised recovery phrase into a different application offers no protection, as the seed phrase itself is the compromised element. A negative result from the checker does not guarantee safety, as Coinspect noted that additional vulnerable address sets may emerge from further analysis of other chains or wallet implementations. Users who are uncertain are advised to migrate to hardware wallets or wallets with documented security evaluations.","heading":"Mitigation and User Guidance","severity":"high","sources":[{"credibility":1,"name":"Ill Bloom: Crypto Wallet Vulnerability — Official Disclosure Site","type":"official","url":"https://illbloom.org/"},{"credibility":3,"name":"Coinspect Security on X — disclosure announcement","type":"social_media","url":"https://x.com/coinspect/status/2073935687770890458"},{"credibility":2,"name":"'Ill Bloom' flaw puts 2,114 digital wallets at risk: report — CoinGeek","type":"news_article","url":"https://coingeek.com/ill-bloom-flaw-puts-2114-digital-wallets-at-risk-report/"}]},{"content":"Coinspect is a blockchain and smart contract security research firm that conducted the investigation leading to the Ill Bloom disclosure. Coinspect stated that it identified five vulnerable wallet implementations, reproduced the attack methodology end-to-end, and coordinated with affected wallet developers and with security firm SlowMist before publishing its findings. The firm published the affected-address dataset and checker tool at illbloom.org and announced the disclosure via its official X (Twitter) account. No independent verification of Coinspect's claims about the number of vulnerable wallets or the completeness of the dataset was available at the time of this investigation; however, the on-chain transaction evidence cited (the May 27, 2026 coordinated sweep of 431 addresses) is verifiable on public blockchains. Multiple Tier 1 and Tier 2 media outlets reported on the disclosure without raising credibility concerns about Coinspect's findings.","heading":"Disclosing Party: Coinspect","severity":"medium","sources":[{"credibility":3,"name":"Coinspect Security on X — disclosure announcement","type":"social_media","url":"https://x.com/coinspect/status/2073935687770890458"},{"credibility":1,"name":"Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html"},{"credibility":2,"name":"Coinspect Warns of Vulnerability Threatening Thousands of Crypto Wallets — ForkLog","type":"news_article","url":"https://forklog.com/en/coinspect-warns-of-vulnerability-threatening-thousands-of-crypto-wallets/"}]},{"content":"As of the July 2026 public disclosure, thousands of vulnerable addresses remain unswept by attackers. Coinspect's dataset of 2,114 addresses represents only a partial view of the full exposure surface. The firm noted that new vulnerable wallets continued to be created close to the disclosure date, suggesting that affected wallet applications may still be in active use by some users. Attackers who are aware of the vulnerability have already demonstrated the ability to execute coordinated mass sweeps across multiple blockchains simultaneously, as evidenced by the May 27, 2026 event. The threat is described as ongoing, and funds in identified vulnerable addresses remain at risk of draining at any time. Users with funds in potentially affected wallets are advised to treat the situation as an active emergency and migrate funds immediately rather than waiting for further disclosure of specific wallet names.","heading":"Ongoing Risk","severity":"critical","sources":[{"credibility":1,"name":"Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html"},{"credibility":2,"name":"Coinspect warns Ill Bloom flaw may drain more crypto wallets — Crypto.news","type":"news_article","url":"https://crypto.news/coinspect-warns-ill-bloom-flaw-may-drain-more-crypto-wallets/"},{"credibility":1,"name":"Ill Bloom: Crypto Wallet Vulnerability — Official Disclosure Site","type":"official","url":"https://illbloom.org/"}]}],"sources_used":[{"credibility":1,"name":"Ill Bloom: Crypto Wallet Vulnerability — Official Disclosure Site (Coinspect)","type":"official","url":"https://illbloom.org/"},{"credibility":1,"name":"Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html"},{"credibility":2,"name":"Coinspect Warns of Vulnerability Threatening Thousands of Crypto Wallets — ForkLog","type":"news_article","url":"https://forklog.com/en/coinspect-warns-of-vulnerability-threatening-thousands-of-crypto-wallets/"},{"credibility":2,"name":"'Ill Bloom' flaw puts 2,114 digital wallets at risk: report — CoinGeek","type":"news_article","url":"https://coingeek.com/ill-bloom-flaw-puts-2114-digital-wallets-at-risk-report/"},{"credibility":2,"name":"Ill Bloom Vulnerability Drains $3.1 Million From Crypto Wallets: Are You Exposed? — BeInCrypto","type":"news_article","url":"https://beincrypto.com/ill-bloom-vulnerability-crypto-wallets/"},{"credibility":2,"name":"Coinspect warns Ill Bloom flaw may drain more crypto wallets — Crypto.news","type":"news_article","url":"https://crypto.news/coinspect-warns-ill-bloom-flaw-may-drain-more-crypto-wallets/"},{"credibility":2,"name":"Thousands of crypto wallets at risk from 'Ill Bloom' vulnerability: Coinspect — TradingView/Cointelegraph","type":"news_article","url":"https://www.tradingview.com/news/cointelegraph:e1ab8d173094b:0-thousands-of-crypto-wallets-at-risk-from-ill-bloom-vulnerability-coinspect/"},{"credibility":3,"name":"Coinspect Security on X — public disclosure announcement","type":"social_media","url":"https://x.com/coinspect/status/2073935687770890458"},{"credibility":2,"name":"Ill Bloom Vulnerability Drains $5 Million from Crypto Wallets — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/06/ill-bloom-vulnerability-crypto-wallets/"}],"summary":"Ill Bloom is an actively exploited cryptographic vulnerability disclosed by blockchain security firm Coinspect in July 2026, stemming from insecure pseudorandom number generators (PRNGs) used during seed phrase generation in certain lesser-known mobile software wallets. Attackers have confirmed drained at least $5 million from over 2,100 identified vulnerable addresses across Bitcoin, Ethereum, Polygon, Tron, Solana, and Rootstock, with wallets remaining at risk as of the disclosure date. The vulnerability is not a scam or fraud entity but represents an ongoing, active-exploitation security threat requiring immediate action by potentially affected users.","timeline":[{"date":"2018-09-01","event":"Earliest known on-chain activity from wallets later identified as vulnerable; affected wallet applications began generating insecure seed phrases using weak PRNGs.","source":"ForkLog / Coinspect disclosure","source_url":"https://forklog.com/en/coinspect-warns-of-vulnerability-threatening-thousands-of-crypto-wallets/"},{"date":"2022-01-01","event":"Historical peak value of identified exposed addresses reached approximately $12.56 million, per Coinspect's on-chain analysis.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html"},{"date":"2026-05-27","event":"Coordinated mass sweep: 431 vulnerable wallet addresses drained across Bitcoin, Ethereum, Rootstock, Tron, and Polygon for approximately $3,140,968 total. Bitcoin losses alone were approximately $2.57 million.","source":"ForkLog / CoinGeek / BeInCrypto","source_url":"https://forklog.com/en/coinspect-warns-of-vulnerability-threatening-thousands-of-crypto-wallets/"},{"date":"2026-06-30","event":"Coinspect's snapshot date for the analyzed vulnerable address dataset: 2,114 funded addresses identified across Bitcoin, Ethereum, Tron, Rootstock, and Polygon.","source":"Coinspect via The Hacker News","source_url":"https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html"},{"date":"2026-07-05","event":"Additional approximately $2 million moved from exposed wallets, including approximately $2.1 million in USDT from a separately identified vulnerable address.","source":"CoinGeek / ForkLog","source_url":"https://coingeek.com/ill-bloom-flaw-puts-2114-digital-wallets-at-risk-report/"},{"date":"2026-07-06","event":"Coinspect publicly disclosed the Ill Bloom vulnerability, publishing findings, on-chain analysis, and an affected-address checker tool at illbloom.org. Confirmed total losses at time of disclosure exceeded $5 million.","source":"The Hacker News / illbloom.org / Coinspect X post","source_url":"https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 9ec35db3-9d74-432b-bf1b-48386a738635
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.